Senior Systems & Security Administrator

Hecker Fink LLP

New York (NY)

On-site

USD 150,000 - 188,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Hecker Fink LLP is seeking a Senior Systems & Security Administrator to manage the Firm’s cloud-first technology stack and oversee controls that support its information security program. The role covers infrastructure administration and security operations across New York and other offices.

The candidate will work within an ISO/IEC 27001 aligned framework, maintaining documented procedures, evidence, and governance.

Qualifications

  • Seven (7) years of systems administration experience, including three (3) or more at a senior level with primary ownership of a production environment.
  • Experience working inside a formal security or compliance program (ISO/IEC 27001, SOC 2, NIST CSF, HIPAA, or equivalent).
  • Certification such as CISSP, CISM, GIAC, or Microsoft SC-100/SC-300/MD-102 preferred but not required.

Responsibilities

  • Administer and secure Microsoft Entra ID, Exchange Online, SharePoint Online, Intune, Defender, and related platforms.
  • Manage Cisco Meraki across multiple offices and cloud-delivered security services.
  • Operate and coordinate security events with SOC provider and Incident Response Plan.
  • Lead automation initiatives using PowerShell, Graph, and platform-native workflows.
  • Support ISO 27001 certification activities and client security assessments.

Skills

Microsoft cloud stack
PowerShell automation
Endpoint security
Documentation & evidence

Education

Relevant security/compliance certification

Tools

Entra ID
Exchange Online
Intune
Meraki
SentinelOne

Job description

Hecker Fink LLP is seeking a Senior Systems & Security Administrator to administer the Firm’s cloud-first technology environment and operate the technical controls that support its information security program. This is a hands-on senior role spanning infrastructure administration and security operations, based in New York and supporting all three offices.

The Firm operates a formal information security management system aligned to ISO/IEC 27001:2022 and is pursuing certification. The successful candidate will have worked inside a governed security program and be comfortable holding to documented procedure and producing evidence of it.

Hecker Fink LLP brings together a high-stakes, cutting-edge litigation practice serving clients across a wide range of practice areas, including commercial litigation, white-collar criminal defense and internal investigations, employment and discrimination, and complex regulatory and securities matters. The firm has also built a pioneering public interest practice geared to the great and urgent challenges of our time.

Since our founding, we have achieved tremendous success and growth, and we seek motivated and talented professionals to join our team.

Responsibilities
  • Work as part of the Firm’s technology group supporting our New York, Washington, DC, and Los Angeles offices, partnering day to day with information security, systems and infrastructure, and end-user support colleagues, and serving as senior technical escalation for the support team.
  • Partner closely with the Chief Information Officer on the hardening and maturation of systems across the technology stack, identifying gaps and bringing forward improvements to configuration, resilience, and control coverage.
  • Identity and access: Administer Microsoft Entra ID — identity lifecycle, conditional access, multifactor and passwordless authentication, privileged access, and single sign-on — and provision, modify, and revoke access under the Firm’s access control standards.
  • Microsoft 365 and endpoints: Administer Exchange Online, SharePoint, OneDrive, Teams, and Purview; manage the Windows endpoint estate through Intune and Autopatch, including compliance policies, configuration profiles, security baselines, application deployment, and Cloud PC provisioning.
  • Network: Administer Cisco Meraki across three offices — firewall policy, VLAN segmentation, wireless, and VPN — together with the Firm’s cloud-delivered web security platform.
  • Security operations: Operate SentinelOne EDR, Microsoft Defender, and the Firm’s data loss prevention and device controls; triage and investigate alerts alongside the Firm’s managed SOC provider and elevate under the Incident Response Plan.
  • Incident response: Serve on the Security Incident Response Team, performing containment, eradication, and recovery under the direction of the Incident Response Technical Lead, and contribute to root cause analysis.
  • Vulnerability and patch management: Remediate findings within defined service levels; manage patching across endpoints, servers, and network firmware; support annual third‑party penetration testing and the remediation that follows.
  • Change and configuration management: Prepare, document, test, and implement changes to production systems, network devices, and firewalls, with approval obtained before implementation; maintain hardening standards and configuration baselines.
  • Backup and recovery: Maintain backup configuration and monitoring, investigate and resolve failures, execute authorized restores, and participate in annual restoration testing.
  • Disaster recovery: Serve as alternate Technical Recovery Lead, maintaining and executing system recovery runbooks and participating in the annual combined business continuity and disaster recovery exercise.
  • Asset and media management: Maintain the inventory of endpoints, mobile devices, network hardware, and software licensing, and handle media in accordance with classification, retention, and destruction requirements.
  • Cryptographic key custody: Serve as a key manager for the Firm’s encryption and credential management platforms.
  • Security program support: Support the Firm’s ISO/IEC 27001 certification program, internal audit, and client security assessments by gathering evidence and remediating findings.
  • Support the Firm’s legal and business platforms in partnership with their owners and vendors, alongside other application and systems support personnel.
  • Automation: Alongside the Firm’s Technology Solutions Engineer, take ownership of the Firm’s existing automations and build new ones — using PowerShell, Microsoft Graph, Intune and Entra configuration, and platform-native workflows — to bring efficiency and consistency to provisioning and deprovisioning, configuration, reporting, evidence collection, and routine maintenance. Document what you build so it can be supported by others.
  • AI-enabled tooling: Administer and secure the Firm’s approved AI platforms, applying the same identity, data protection, and logging controls that govern the rest of the environment, and help evaluate new capabilities and the controls they require. Act as an informed advocate for responsible AI use, helping colleagues understand what the tooling can do while ensuring appropriate human oversight.
  • Develop and document technical processes, procedures, and runbooks, and keep system documentation current as the environment changes.
Qualifications
  • Education and Experience: You have at least seven (7) years of systems administration experience, including three (3) or more at a senior level with primary ownership of a production environment, and you have worked inside a formal security or compliance program — ISO/IEC 27001, SOC 2, NIST CSF, HIPAA, or equivalent — including direct participation in audits or client security assessments. A relevant certification — e.g., CISSP, CISM, GIAC, or Microsoft SC-100, SC-300, or MD-102 — preferred but not required.
  • Knowledge and Skills: You have deep, current administration experience across the Microsoft cloud stack (Entra ID including conditional access, Exchange Online, SharePoint Online, Intune, and Defender), practical experience with enterprise network infrastructure (firewall policy, segmentation, wireless, and VPN), working command of endpoint security operations, and fluency automating routine administration — you are comfortable inheriting and maintaining automations built by others as well as writing your own, in PowerShell, Microsoft Graph, or comparable tooling.
  • Documentation and Evidence: You keep change records, runbooks, configuration baselines, and audit evidence as a matter of habit, and you can produce them on request without reconstructing them after the fact.
  • Clear Communication and Attention to Detail: You express yourself clearly and concisely, always highlighting the most important information, including when explaining technical positions to non-technical colleagues and clients. You proactively communicate the status of your work and share updates with colleagues when necessary. You ensure that your work is mistake free.
  • Judgment with Privileged Access: You exercise restraint with administrative access, understand why approval and separation‑of‑duties boundaries exist, and work within them.
  • Confidentiality: You must be able to adhere to Firm policies regarding the protection of confidential data and demonstrate sensitivity to (and good judgment in connection with) confidential attorney, personnel, and Firm matters.
  • Ownership, Initiative, and Teamwork: You are a dedicated self-starter who takes ownership of your projects and follows through on their completion. You proactively anticipate, communicate, and work independently and resourcefully to resolve obstacles you encounter in your work. You possess a strong customer-service orientation and ability to work well within a team as well as the ability to be a brand champion.
  • Organization and Project Management: You are comfortable balancing tasks of varying levels of urgency and complexity and work well under pressure with tight deadlines.
  • Flexibility: You are flexible to be available after hours to assist with infrastructure and security issues, including during declared incidents. You are comfortable in an environment where your responsibilities may vary from day to day. You demonstrate a "no job too big, no job too small" attitude, and take a collaborative, team-focused approach to rejuggling priorities and contributing to tasks across the Firm.
  • Mission Orientation: You are enthusiastic and passionate about our commitment to civil rights and public interest law. You thrive when your work is connected to purpose.

In addition, the successful candidate will be based in the New York area or willing to relocate.

Compensation

The expected base salary for this role ranges from $150,000 - $188,000 and is dependent on experience.

Additional Information

You must be fully vaccinated against COVID-19 by your hire date to be eligible for starting in the role.

Hecker Fink LLP is committed to fostering a workplace in which individuals from all backgrounds are welcomed, treated with respect, and given every opportunity to contribute, develop, lead, and reach their highest potential. As an equal opportunity employer, it is the Firm’s policy to ensure all employment decisions are made without discrimination based on race, color, religion or religious belief, sex, sexual orientation, gender identity/expression, national origin, immigration or citizenship status, disability, age, military or veteran status, marital status or civil partnership status, pregnancy or related medical conditions, or any other basis protected by federal, state or local civil rights law, ordinance or regulation. This policy applies to recruiting, hiring, placement, leaves of absence, compensation and all other terms and conditions of employment. Hecker Fink provides reasonable accommodation to qualified individuals with a disability in compliance with applicable laws and regulations. Please note that applicants must be authorized to work in the United States. All qualified applicants are encouraged to apply.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. IT Support Technician
Sr. IT Support Technician

Hecker Fink LLP • Los Angeles (CA)

Hybrid
USD 90,000 - 110,000
Office Manager
Office Manager

Hecker Fink LLP • Washington

On-site
USD 125,000 - 140,000
Business Development and Marketing Manager
Business Development and Marketing Manager

Ambition • New York (NY)

Hybrid
USD 150,000 - 180,000
Staff Attorney
Staff Attorney

Hecker Fink LLP • Washington

On-site
USD 125,000 - 140,000
Job Posting Title Sr. Systems Engineer
Job Posting Title Sr. Systems Engineer

Willkie Farr & Gallagher LLP • New York (NY), Northern (KY)

Hybrid
USD 170,000 - 180,000
Security Engineer
Security Engineer

Manatt, Phelps & Phillips, LLP • New York (NY)

Hybrid
USD 80,000 - 100,000
Sr. Systems Engineer
Sr. Systems Engineer

Willkie Farr & Gallagher LLP • New York (NY)

On-site
USD 170,000 - 180,000
Job Posting Title Cloud Delivery Engineer
Job Posting Title Cloud Delivery Engineer

Willkie Farr & Gallagher LLP • New York (NY), Northern (KY)

Hybrid
USD 150,000 - 180,000
Security Engineer
Security Engineer

Cricket Wireless LLC. • Los Angeles (CA)

On-site
USD 80,000 - 100,000
Security Architect
Security Architect

Brooksource • Denver (CO)

Hybrid
USD 170,000 - 230,000
Competitive benefits
401k with company match
Paid time off